Bug 29254 - apache-commons-compress new security issues fixed upstream in 1.21 (CVE-2021-3551[5-7] and CVE-2021-36090)
Summary: apache-commons-compress new security issues fixed upstream in 1.21 (CVE-2021-...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-07-13 17:38 CEST by David Walser
Modified: 2022-01-11 08:13 CET (History)
6 users (show)

See Also:
Source RPM: apache-commons-compress-1.20-1.mga8.src.rpm
CVE:
Status comment:


Attachments

David Walser 2021-07-13 17:38:55 CEST

Status comment: (none) => Fixed upstream in 1.21
Whiteboard: (none) => MGA8TOO

Comment 1 David Walser 2021-08-06 00:24:39 CEST
openSUSE has issued an advisory for this today (August 5):
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XVOH7P2WI6SSS2OORQJBS45T5SKKO7BV/
Nicolas Lécureuil 2021-11-25 22:46:30 CET

Version: Cauldron => 8
CC: (none) => mageia
Whiteboard: MGA8TOO => (none)

Comment 2 David Walser 2021-11-26 01:25:39 CET
apache-commons-compress-1.21-1.mga9 uploaded for Cauldron by Nicolas.
Comment 3 Nicolas Lécureuil 2021-12-14 00:59:34 CET
updated in mga8:

src:
    - osgi-core-8.0.0-1.mga8
    - apache-commons-compress-1.21-1.mga8

Assignee: java => qa-bugs
Status comment: Fixed upstream in 1.21 => (none)

Comment 4 David Walser 2021-12-14 01:47:50 CET
osgi-core-8.0.0-1.mga8
osgi-core-javadoc-8.0.0-1.mga8
apache-commons-compress-1.21-1.mga8
apache-commons-compress-javadoc-1.21-1.mga8
Comment 5 Herman Viaene 2021-12-14 16:02:33 CET
MGA8-64 Plasma on Lenovo B50 in Dutch
No installation issues.
Trying to follow Len's example from bug 22787 Comment 12.
Created a folder popapachecompressin my Documenten, copied the testfilesinto it and a zipfile of mine. Created in that folder another folder to contain the extracted files.
$ cd Documenten//pocapachecompress/
$ javac -cp .:"/usr/share/java/apache-commons-compress.jar" Zipextract.java
[tester8@mach5 pocapachecompress]$ ls
extraction/  Merksem.zip  Zipextract.class  Zipextract.java  Zipup.java
then copied command, but got
$ java -cp .:"/usr/share/java/apache-commons-compress.jar" Zipextract 
Error:  format is Zipextract <zip file> <extract location>
So tried
$ java -cp .:"/usr/share/java/apache-commons-compress.jar" Zipextract Merksem.zip extraction/
That gave no error, but when I look at what had been extracted

$ cd extraction/
[tester8@mach5 extraction]$ ls
'Merksem Logo.ai'
But the zip file contains a folder "_MACOXS" and three image files Merksem, one.ai as shown, one eps and one png.
I don't know what to think of this result.

CC: (none) => herman.viaene

Comment 6 Brian Rockwell 2022-01-04 17:42:50 CET
252  javac -cp .:"/usr/share/java/apache-commons-compress.jar" Zipup.java
  253  java -cp .:"/usr/share/java/apache-commons-compress.jar" Zipup
  254  journalctl > jrn.txt
  255  ls -ltr
  256  ll
  257  java -cp .:"/usr/share/java/apache-commons-compress.jar" Zipup
  258  java -cp .:"/usr/share/java/apache-commons-compress.jar" Zipup jrn.txt jrn.zip
  259  ls -ltr
  260  javac -cp .:"/usr/share/java/apache-commons-compress.jar" Zipextract.java
  261  ls -ltr
  262  rm *.txt
  263  java -cp .:"/usr/share/java/apache-commons-compress.jar" Zipextract jrn.zip .


worked for me.  

Does anyone want me to write the routine for 7z testing?

CC: (none) => brtians1

Brian Rockwell 2022-01-04 17:44:36 CET

Whiteboard: (none) => MGA8-64-OK

Comment 7 Thomas Andrews 2022-01-07 04:31:55 CET
Len's comment in the bug Herman cited thanked Brian for his help, so it would appear that Brian has the most experience with these packages. Therefore, I'm going with his OK.

Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2022-01-11 01:20:57 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 8 Mageia Robot 2022-01-11 08:13:55 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0009.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.